CVE-2024-20282
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device.
This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this token to access resources within the device infrastructure. A successful exploit could allow an attacker to gain root access to the filesystem or hosted containers on an affected device.
Una vulnerabilidad en Cisco Nexus Dashboard podría permitir que un atacante local autenticado con credenciales válidas de usuario de rescate eleve los privilegios a root en un dispositivo afectado. Esta vulnerabilidad se debe a protecciones insuficientes para un token de acceso confidencial. Un atacante podría aprovechar esta vulnerabilidad utilizando este token para acceder a recursos dentro de la infraestructura del dispositivo. Un exploit exitoso podría permitir a un atacante obtener acceso raíz al SYSTEM de archivos o a los contenedores alojados en un dispositivo afectado.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-08 CVE Reserved
- 2024-04-03 CVE Published
- 2024-04-04 EPSS Updated
- 2024-08-27 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndru-pesc-kZ2PQLZH |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 1.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.0 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.0 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.0 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.0 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.1 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.2 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.2 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.2 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.3 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.3 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.3 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.3 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 2.3 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "2.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 3.0 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "3.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Nexus Dashboard Search vendor "Cisco" for product "Cisco Nexus Dashboard" | 3.0 Search vendor "Cisco" for product "Cisco Nexus Dashboard" and version "3.0" | en |
Affected
|